[SECURITY] [DLA 1797-1] drupal7 security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Package : drupal7
Version : 7.32-1+deb8u17
CVE ID : CVE-2019-11358 CVE-2019-11831
Debian Bug : 927330 928688
Several security vulnerabilities have been discovered in drupal7, a
PHP web site platform. The vulnerabilities affect the embedded versions
of the jQuery JavaScript library and the Typo3 Phar Stream Wrapper
library.
CVE-2019-11358
It was discovered that the jQuery version embedded in Drupal was
prone to a cross site scripting vulnerability in jQuery.extend().
For additional information, please refer to the upstream advisory
at https://www.drupal.org/sa-core-2019-006.
CVE-2019-11831
It was discovered that incomplete validation in a Phar processing
library embedded in Drupal, a fully-featured content management
framework, could result in information disclosure.
For additional information, please refer to the upstream advisory
at https://www.drupal.org/sa-core-2019-007.
For Debian 8 "Jessie", these problems have been fixed in version
7.32-1+deb8u17.
We recommend that you upgrade your drupal7 packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- --
Jonas Meurer
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEELIzSg9Pv30M4kOeDUmLn/0kQSf4FAlzit/4ACgkQUmLn/0kQ
Sf7Vnw/+MlRUrgDnbKvlAERr6TDph9kcSwl9rbi4kElY3vj0xQZGnaX2HZGYyHHT
uUr9xp3JY6UyLrWQLiBmPdtRKTF2dHkTpEna9lrn8JXXMpZsKohkpEmotBfiG4E5
FdkAZtVwcn+4FrnLSvkJrxn9U8huokwEYypSk7lj2OUtXJu1qpYO5pGcRpCGH3Bn
3U3IaAwf+zZvB118GzgBJThbkOMvhIHWLE55E6aUx7navEw87blyvnv/t+f8yEzB
wiGVL3sIyxpZau2k3pvMm36ytplP5rD/1UpvyB7Vvqv1uu/1E/+8GdpuishUqSVO
T2xiwjIAzAqP1SiJzXWx103poNlhHPFAj8Z/xFqybs/HfMgIEFK60oulZYDRBXo8
+gQ+dH10oM14Qrfgyiwa+TydkSsGqAg5rDN5m1Uj5ncNcRQeQ+vCDoiJefTid/55
KPTkswqgUoZReIDTZ0q0f902gjgpp8uOsuJZUwvrjM8neI6pMm3scJqrns8K5K2B
TyNTvtWc/muhhYeB3si9vXM8Ou6uvb2MG+8UT2WqEd4L1VCo7ty46CQSx+h0XHJt
BeVbhQEJKYAUCR0W0Wrbux9gV3Z5R054YuIGklUreirmw4vqsDZ+Xf+EexRetWNH
DdQIuUVSv2UQ7juqTdgsGbEz7JgnUw5wp+eSjuQ1gHvJ7q387GQ=
=LBM6
-----END PGP SIGNATURE-----
Reply to: